NEWS
AI Agents Can Act, but Someone Has to Own Them
A 2026 expert panel, a 2024 chatbot ruling, and live EU transparency rules all point to the same bottleneck: named people must own what agents do.
72% of a 2026 MIT Sloan Management Review and Boston Consulting Group expert panel agree that responsible governance fails if it treats AI agents as autonomous decision makers. The panel, more than 50 academics and operators in its fifth year, is not arguing that agents sit idle.
They plan, call tools, move inventory, and transact without a person approving every step. The second effect of that operational freedom is the one boards will feel: someone with a name, a budget, and a lawyer still has to own the result, and those people are already in short supply.
Seventy-Two Percent of the Experts Draw the Same Line
EnBW chief data officer Rainer Hoffmann said agentic autonomy is real and growing. Ben Dias, chief AI scientist at IAG, said agents are moving past answers and into action on a company’s behalf. Simon Chesterman, vice provost at the National University of Singapore, noted that agentic systems can plan, call tools, transact, and run across workflows. Linda Leopold, an AI speaker and consultant, put it in engineering terms: they act without constant human sign-off.
Bruno Bioni, founder of Data Privacy Brasil, called that picture delegated execution. The agent selects steps and uses tools inside limits someone else set. Amit Shah, CEO of Instalily.ai, described the same pattern as infrastructure that decides in an operational sense: it routes the order, moves stock, prices the risk. Chesterman’s split is the one that matters for counsel. Autonomy in the engineering sense is not autonomy in the moral or legal sense.
A machine can make the call, Shah said, but it cannot own the outcome. Jai Ganesh, formerly Wipro’s vice president of technology, said agents can choose and execute and still cannot be held to account for what follows. Carolina Aguerre, a professor at Universidad Católica del Uruguay, called responsibility a human faculty. Riyanka Roy Choudhury, a Stanford CodeEx fellow, said treating the agent as the decision maker severs liability from capacity, because the software holds no assets, no license, and no interest a court can deter.
THE 2026 PANEL, IN BRIEF
- The vote: 72% agree or strongly agree that responsible governance treating agents as autonomous decision makers will fail.
- The roster: More than 50 practitioners, academics, researchers, and policy makers, convened for a fifth year with BCG.
- The warning: Operational independence is growing faster than mapped failure modes, said Renato Leite Monteiro, vice president of privacy, data protection, AI, and intellectual property at e&.
- The authors: Elizabeth M. Renieris, David Kiron, Steven Mills, and Anne Kleppe framed the findings as a governance problem, not a model problem.
Shah called “autonomous decision maker” a governance fiction that enables blame laundering with better vocabulary. Bioni said it lets developers, deployers, and users hide behind “the AI decided” when results go wrong. That is the vacuum. Employees start to believe the agent ate the mistake. The company remains the party a tribunal can order to pay.
The Chatbot That Could Not Be Sued
In November 2022, Jake Moffatt used the chatbot on Air Canada’s website after his grandmother died. It told him bereavement fares could be claimed after travel. He bought tickets at the full rate, applied as instructed, and was refused. Air Canada’s defence, as the Civil Resolution Tribunal read it, treated the bot as if it were a separate actor.
In effect, Air Canada suggests the chatbot is a separate legal entity that is responsible for its own actions. This is a remarkable submission. While a chatbot has an interactive component, it is still just a part of Air Canada’s website. It should be obvious to Air Canada that it is responsible for all the information on its website. It makes no difference whether the information comes from a static page or a chatbot.
Christopher C. Rivers, Tribunal Member, Moffatt v. Air Canada, 2024 BCCRT 149
The February 2024 Air Canada chatbot ruling ordered the airline to pay Moffatt C$812.02, made up of C$650.88 in damages, C$36.14 in pre-judgment interest, and C$125 in tribunal fees. Rivers found the airline did not take reasonable care to keep the chatbot accurate, and that a customer should not have to check one part of a site against another. File SC-2023-005609 is small-claims money. The legal point travels: a system that talks like staff is still the company’s mouth.
Chesterman’s caution sits on that record. The more firms speak as if agents decide, the easier it becomes to launder responsibility through the machine. The model recommended, the agent acted, the human shrugged. A bereavement fare is a cheap version of that shrug. Pricing risk, moving money, or locking a worker out of a shift is the expensive one.
Who Owns an Agent’s Irreversible Action?
A specific role or person, named before the agent goes live, who has the training and the power to stop it. Boards, courts, and deployer rules all look for a natural person. The agent cannot fill that seat, and a policy memo cannot either if the permissions in production ignore it.
The 2026 panel’s practical list is blunt. Calibrate autonomy by the stakes and by whether the act can be reversed, not by what the model can do. Build limits into architecture with scoped permissions, approval gates, and hard stops, rather than hoping a prompt will be obeyed. Assign clear ownership for outcomes to roles, and do it before launch. Govern the system around the agent: the builder, the enterprise, the data and tools, the permissions, and the people who benefit. Reward staff who challenge the agent, because a culture that punishes pushback will rubber-stamp bad output.
Katia Walsh, AI lead at Apollo Global Management, and Richard Benjamins, co-CEO of RAIght.ai, both leave room for low-stakes work to run without a human on every click. Pierre-Yves Calloc’h said the line is knowing exactly where autonomy must stop, especially where outcomes rest on trade-offs and value judgments that cannot be fully encoded. Aguerre said autonomy should be set against the task and the risk, not granted as a personality trait of the software.
That is where the hidden cost shows up. The named human is often a middle manager who did not train the model, cannot see every tool call, and is still the name a regulator will ask for. Mark Surman, president of Mozilla, said agents do not come from nowhere: people build them, companies deploy them, and someone profits. Stefaan Verhulst of GovLab said governance has to treat agents as participants in a wider system of institutions, data, incentives, law, and public expectation. Logging what happened is not the same as proving someone allowed that step. An agent can be fully observable and still be holding permissions nobody signed for that action.
THE LIABILITY SPLIT
| Party | What it can do | What it cannot do |
|---|---|---|
| The agent | Plan steps, call tools, transact inside its sandbox | Hold assets, be sued, or own the moral result |
| The builder | Set data, tools, and default limits | Stand in for the live owner after deployment |
| The deploying firm | Authorize use and take the gain | Point at “the AI” when a customer or court asks |
| The named overseer | Override, halt, and escalate | Transfer the outcome back onto the software |
Öykü Işik’s point cuts through the table. Agents are stochastic and context-dependent, not coherent actors with stable intent. Accountability that needs intent will not find it in the weights. It has to live in the org chart.
High-Risk Oversight Is Timed for Late 2027
The European Commission’s AI Act entered into force on 1 August 2024 and became generally applicable on 2 August 2026. From that day the AI Office and member-state authorities supervise and enforce, and the Article 50 transparency duties apply, including the requirement that people know when they are talking to a machine. Prohibited practices have applied since February 2025. Rules for general-purpose AI models have applied since August 2025.
The hard human-oversight package for Annex III systems did not land with that August date. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved those duties. Strict obligations for high-risk AI systems from 2 December 2027 now include risk assessment, data quality, logging, documentation, information for the deployer, human oversight, robustness, and cybersecurity. AI embedded in Annex I product-safety regimes is timed for 2 August 2028.
Article 14, when it binds, is not a slogan. High-risk systems must be designed so natural persons can oversee them in use. Oversight has to match the risk, the level of autonomy, and the context. People assigned to that job must understand limits, watch for automation bias, interpret output, disregard or reverse it, and interrupt the system with a stop control that leaves it in a safe state. Deployers have to give those people competence, training, authority, and support. For some remote biometric identification, two qualified people must confirm an identification before the deployer acts on it.
Non-compliance with prohibited practices can draw administrative fines of up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Other operator breaches sit in a band of up to EUR 15 million or 3%. Those figures are already in the Act. The delay on high-risk duties is a calendar fact, not a pause on customer-law cases like Moffatt, and not a pause on chatbot disclosure.
THE DATES THAT BIND
- 14 February 2024: The Civil Resolution Tribunal holds Air Canada liable for its chatbot’s bereavement-fare advice.
- 22 January 2026: Singapore’s IMDA launches its Model AI Governance Framework for Agentic AI at Davos.
- 20 May 2026: IMDA updates that guidance with industry cases.
- 2 August 2026: The EU AI Act’s general application and Article 50 transparency rules take effect.
- 2 December 2027: Annex III high-risk duties, including designed human oversight, are scheduled to apply.
A 15-month-class gap before those high-risk controls bind is long enough for a messy habit to set. Firms can ship agents that act across tools now, then retrofit stop buttons later. The tribunal in British Columbia did not wait for Brussels.
Singapore Wrote Humans Into the Approval Gate
At Davos on 22 January 2026, Josephine Teo, Singapore’s minister for digital development and information, announced IMDA’s Model AI Governance Framework for Agentic AI. The launch text is plain: technical and non-technical measures, and a reminder that humans are ultimately accountable. On 20 May 2026 IMDA folded in feedback from 60+ organisations, among them AWS, DBS, Google, and Salesforce, plus 10+ live deployment cases from names such as Ant International, GovTech, OCBC, PwC, Tencent, and Workday.
The four dimensions match the panel’s second-order problem more closely than a principles poster. Bound the risk up front by picking use cases and limiting autonomy, tools, and data access. Make humans meaningfully accountable with checkpoints that actually require approval. Put technical controls through the agent’s life, including baseline tests and whitelisted services. Give end users a way to carry their share when they sit outside the deploying firm. Later notes split platform providers from app developers and tell operators to watch override rates and response times, because a human who never disagrees is not overseeing anything.
Belona Sonna of the Australian National University used driving to make the other half of the case. Some domains need agents to act in real time. The job is keeping that behavior aligned with purpose and values, not pretending the car has no driver in law. Calloc’h’s high-stakes warning still applies there. Trade-offs among conflicting goals are governance choices. They do not belong in an unbounded tool loop.
Trivial Work Versus Binding Trade-Offs
Walsh and Benjamins are right that a password reset is not a credit file. The failure mode is classification drift. Once “name a human” is the price of a high-stakes agent, product teams have a reason to file more work under trivial so the agent can keep moving. Legal, audit, and insurance have a reason to file the same work as material. That argument, not model quality, will set the pace of rollout.
A November 2025 MIT SMR-BCG global executive study found that 76% of respondents already agentic AI as more like a coworker than a tool. Agentic systems had reached 35% adoption in two years, with another 44% planning to deploy soon, or 79% on one side of that line. Traditional AI took eight years to reach 72% adoption. Generative AI hit 70% in three. Leopold’s worry follows from those figures. If staff start treating agents as colleagues with agency, the shrug Chesterman described becomes workplace common sense, and the named owner becomes a fiction on an org chart.
You cannot govern an agent you cannot see across systems, and a list of bot names is not an inventory. The fields that set the risk tier are who is affected, what data moves, which decisions change, and who was allowed to permit that step. Mike Linksvayer, vice president of developer policy at GitHub, said in a related 2026 panel that as systems become more agentic, the limit is no longer checking each output. It is informed judgment over goals, constraints, escalation paths, and responsibility. That is a staffing problem dressed up as a software problem.
WHERE AUTONOMY SHOULD STOP
- Hard stops: Payments, legal commitments, medical or safety acts, and any step that cannot be undone without harm stay behind an approval gate with a named owner.
- Scoped tools: Agents get an allowlist of APIs and data, not a browser and a hope, and production stays separate from test.
- Override evidence: Teams track how often people reject the agent and how long they take, because a 100% accept rate is a rubber stamp.
- Cross-silo owners: If an agent writes in sales and bills in finance, each function documents its watch, its escalation path, and its share of the outcome before go-live.
The panel’s fifth recommendation, a culture in which people can challenge agents and get credit for it, is the one most likely to lose a budget fight. Throughput metrics pull the other way. External agents sold as products make it worse, because the deploying firm can demand less of a customer than it can of its own staff. In those cases the only reliable control is the one compiled into the product: permissions, halt, and a signature that cannot be an API token.
Accountability Structures Inside the NIST Framework
In the United States the binding instrument is still mostly customer law and contract, not an AI Act analogue. The National Institute of Standards and Technology’s AI Risk Management Framework 1.0, published in 2023 and still the reference core, already tells organizations to put accountability structures for named AI teams in place. Govern 2.1 wants roles and communication lines documented and clear. Govern 2.2 wants training so people can actually do the job. Govern 2.3 puts executive leadership on the hook for deployment decisions. Govern 3.2 asks for policies that separate human and AI roles and define oversight. Map 3.5 wants human oversight processes defined and written down, not implied.
None of that names the agent as the accountable party. It names teams, partners, and executives. That is the same landing zone as the 2026 panel, the IMDA checklist, and Article 14, even while the EU’s high-risk clock still reads 2 December 2027. The scarce input is people who understand the agent’s limits, have authority to halt it, and will still be employed when the letter arrives.
Firms that want speed without that signature are buying the Air Canada defence in bulk. The bot can talk. The order still has a name on it, and it will not be the model’s.
Disclaimer: This article is news reporting and analysis of expert-panel findings, court and tribunal records, and public AI rules. It is informational only and is not legal, compliance, insurance, or governance advice for any organization or person. Readers who need to design agent permissions, assign liability, or interpret the EU AI Act, NIST guidance, or national rules should consult a qualified lawyer or compliance professional licensed in the relevant jurisdiction. Figures, panel results, and regulatory dates reflect the cited sources as published and may change as agencies, courts, and companies update their positions.
-
NEWS3 days agoCheaper Tokens Made AI Deployments Cost Enterprises More
-
NEWS3 days agoLG Smart TVs Still Scan Homes Behind Apple TV
-
GAMING3 days agoOcarina of Time’s Australia Listing Matches Yoshi at $59.99
-
NEWS3 days agoSembly 3.0 Makes Branded Decks and Shifts the Bottleneck
-
NEWS3 days agoNewark’s Phone Ban Starts as a Storage Problem
